Satisfy gosec on the proxy count and the request log
G115: the trusted-proxy count is stored as an int64 instead of narrowing it to int32. G706: the request logger and serverError quote the request method and route; the logger's remaining taint comes from the wrapped response writer, so it carries a justified nosec like the other quoted log lines. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
This commit is contained in:
@@ -77,7 +77,7 @@ func serverError(w http.ResponseWriter, r *http.Request, err error) {
|
||||
if rc := chi.RouteContext(r.Context()); rc != nil && rc.RoutePattern() != "" {
|
||||
route = rc.RoutePattern()
|
||||
}
|
||||
log.Printf("%s %s: %v", r.Method, route, err)
|
||||
log.Printf("%s %s: %v", strconv.Quote(r.Method), strconv.Quote(route), err)
|
||||
respond(w, http.StatusInternalServerError, errResp("internal error"))
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user